One On-Chain Transfer Could Lead to 14 Years in Prison? UK Crypto Compliance Faces New Risks

marsbitPublished on 2026-07-20Last updated on 2026-07-20

Abstract

A blockchain transfer could now lead to a 14-year prison sentence in the UK, following the designation of Iran's Islamic Revolutionary Guard Corps (IRGC) under the National Security Act 2023. A new criminal offense (Section 17C) makes it illegal for UK-linked persons or entities to obtain, receive, or retain any valuable benefit if they know, or should reasonably know, it originates from a designated entity like the IRGC. This applies broadly to crypto assets and on-chain transfers. The key challenge lies in timing and knowledge. A transfer can settle on-chain before the recipient identifies the sending wallet, and wallet attribution to a sanctioned entity may only occur post-transaction. Liability depends on what the recipient knew about the source of funds and when they knew it. The offense follows the value, not the payment path, and can involve indirect provision through intermediaries. While the designation itself doesn't trigger automatic asset freezes under UK sanctions law, it creates a separate criminal risk. For UK crypto exchanges, custodians, payment firms, and even users, this makes maintaining clear records of wallet attribution, transaction timelines, and subsequent actions critical for evidence. The law does not impose new reporting duties but emphasizes using existing suspicious activity reporting and consent processes. The lack of ability to reject on-chain transactions makes documented internal controls and decision-making timelines vital for legal defens...

Author: CryptoSlate / Liam 'Akiba' Wright

Compiled by: TechFlow

TechFlow Introduction: A cryptocurrency payment might settle in seconds, but if a wallet is later identified as being linked to Iran's Islamic Revolutionary Guard Corps (IRGC), UK companies and individuals could face up to 14 years in prison. This is not an anti-money laundering fine, but a criminal offense—even if the blockchain transfer was completed before you identified the wallet's affiliation. For the crypto industry, this means wallet attribution and the timeline of awareness become a critical evidence chain of life-and-death importance.

The UK's designation of Iran's Islamic Revolutionary Guard Corps (IRGC) took effect on July 17, creating new criminal risks for UK-connected persons and businesses that receive or retain value linked to the organization.

According to the designation documents, the IRGC is one of the first three entities listed in Schedule 6A of the 2023 National Security Act.

The new Section 17C offense stipulates that a person who obtains, accepts, or retains a qualifying material benefit, and knows—or ought reasonably to know based on other facts known to them—that the benefit is from a designated entity, can face up to 14 years in prison.

The rules still leave some room for judgment. Payments connected to Iran do not automatically constitute a crime, and the Schedule 6A designation itself does not trigger asset freezes and transaction prohibitions under UK sanctions law. The key issues are whether the value can be linked to the IRGC and what the recipient knew at the time. Freezing stablecoins would still require separate action from the issuer or other legal authority.

The law never mentions crypto assets, but its wording is broad enough to cover them. It covers money or anything of value provided directly or indirectly, including through a company, which could bring stablecoins and other on-chain transfers within scope.

For exchanges, custodians, issuers, payment businesses, or UK users, this makes wallet attribution and timing an operational issue. A blockchain network might complete a transfer before the recipient can reject it, and an address might only be linked to a designated entity afterwards.

The core question becomes: what was known about the wallet and counterparty, and when, and what happened to that value afterwards.

Offense Follows Value, Not Payment Path

Section 17C(1) applies not only to payments made directly to a person. It can also apply when a person obtains or accepts a benefit for another, or retains a benefit already received. The key questions are whether the benefit is from a designated entity and whether the recipient knew or ought reasonably to have known of that connection.

The phrases "by or on behalf of" and "directly or indirectly" are important in a market built around intermediaries. The payment need not come from a wallet labeled "IRGC" or from an entity using the organization's name.

The supply chain can run through companies or other intermediaries. However, an Iranian counterparty, an Iran-linked wallet, or a crypto payment itself does not establish that the IRGC provided the benefit. Prosecution would still require a connection to the designated entity and the required subjective element.

The maximum sentence depends on the conduct. Upon conviction on indictment, the Section 17C(1) offense involving obtaining, accepting, or retaining a benefit carries a maximum of 14 years' imprisonment and a potential fine.

The Section 17C(2) offense of agreeing to obtain, accept, or retain a benefit carries a maximum of 10 years' imprisonment and a potential fine. A Home Office announcement broadly describes the regime as carrying up to 14 years, while the legal text provides this distinction.

Sending value in the other direction follows a separate statutory path. Section 17B covers conduct intended to materially assist a designated entity in UK-related activities. It also covers conduct likely to provide such assistance when the person knows, or based on known facts ought reasonably to know, that it may provide that assistance. Receiving and assisting are distinct offenses with different elements; neither creates a comprehensive prohibition on Iranian crypto activity.

The law also retains targeted protections. A financial benefit is excluded when it is a reasonable consideration for goods or services, and providing them is not itself an offense. Other provisions cover having a reasonable excuse for retaining or providing information, qualifying legal obligations and public functions, and humanitarian activities conducted in accordance with internationally recognized applicable principles and standards. Their application still depends on specific facts.

On-Chain Settlement Makes Timing a Challenge

The Office of Financial Sanctions Implementation (OFSI)'s crypto asset threat assessment (concerning sanctions, not the new designated entity offenses) states that crypto firms cannot reject incoming blockchain transactions. It also notes that addresses may be attributed later, and analytical tools can identify historical direct or indirect risks.

These observations describe the same technical sequence that UK-connected recipients must now consider. A deposit may complete before a custodian has reliable identity for the sending wallet. New intelligence may later link that address or a set of related addresses to a designated entity after completion.

An initially unidentified receipt does not automatically constitute a crime. The timeline may instead become crucial evidence.

A reliable record may need to show the transaction time, wallet risk data available then, counterparty information, when an attribution alert appeared, the basis and confidence of that alert, whether the value remains accessible, and the escalated response.

Receiving and retaining may also occur at different points. Network-level finality may prevent a recipient from reversing the original transfer, while separate account or token controls may affect what happens next.

A custodian may be able to restrict account access, block subsequent withdrawals, investigate the source, or seek appropriate consent pathways. The necessary response depends on the facts and applicable legal systems.

UK Connection Follows the Funds

Section 17C can apply to conduct wholly outside the UK when the benefit is provided in or from the UK, the person is a UK person, or there is a specific Crown connection. UK persons include UK nationals, individuals resident in the UK, entities incorporated under UK law, and unincorporated associations formed under UK law.

This scope brings more entities beyond regulated trading venues into the potential review population. UK-related exchanges and custodians are the most obvious examples as they receive and hold client assets.

Payment processors, OTC desks, merchants, and other businesses may facilitate or retain on-chain value. Some stablecoin issuers, depending on their token architecture and permissions, can restrict subsequent token use after attribution. Ordinary UK-related users can also receive value, subject to the same designated entity link and knowledge threshold.

The government's impact assessment states the Act does not create new reporting obligations for businesses. Nonetheless, it considers businesses that receive, hold, or move funds on behalf of designated entities and encourages the use of existing suspicious activity and consent processes. Applying the same logic to crypto goes beyond what the law explicitly requires.

Governance may affect risk. Under Section 35 of the 2023 National Security Act, an officer may be liable alongside an entity when a Part 1 offense is committed with their consent or connivance, or is attributable to their neglect. Directors are not automatically liable for every flagged wallet, but escalating ownership and written follow-up now carry higher stakes.

Designation Separate from Sanctions Freezing

Schedule 6A and UK financial sanctions perform different legal functions. A government factsheet states that an organization listed solely under sanctions is not within the scope of the designated entity offenses unless also designated for these offenses.

Adding an entity to Schedule 6A does not itself trigger the asset freeze, transaction prohibitions, and reporting obligations that arise under financial sanctions law. It also does not alter stablecoin smart contracts. Issuer freezing depends on separate sanctions obligations, other legal bases, or actions taken under the issuer's own control.

The case of Tether freezing 134 wallets illustrates the technical dimension. The issuer used its control over its tokens to freeze addresses in a sanctions context. The new UK issue is different: whether a person accepted or retained a benefit linked to a designated entity with the requisite knowledge, including when no issuer has frozen anything.

Thus, workflows limited to sanctions have gaps. Businesses may need to separate Schedule 6A attribution alerts from OFSI asset freeze matches and then determine which legal and operational escalation paths apply.

A wallet could raise issues under both regimes, but the presence or absence of a sanctions freeze does not resolve Section 17C liability.

Controls Need an Evidence Timeline

For UK-connected crypto businesses that receive, hold, transfer, or facilitate value, a practical response may be to review how existing controls preserve the chronological sequence behind decisions.

The Act itself does not impose this crypto-specific checklist, but the offense and official crypto risk materials support reviewing how businesses:

Map designated entities, aliases, and related counterparties separately from financial sanctions lists;

Record the source, confidence, and timing of wallet attributions;

Re-screen earlier deposits when reliable attribution changes;

Link on-chain findings with client, company, and intermediary information;

Escalate uncertain matches without treating proximity to an Iran-linked wallet as proof; and

Document decisions regarding access, retention, withdrawals, and existing reporting or consent pathways.

UK crypto asset exchanges and custodial wallet providers already operate under the FCA's AML framework, which expects proportionate transaction monitoring and internal escalation. Schedule 6A adds separate potential criminal risk to the facts these systems may uncover.

Targeted statutory protections are not equivalent to a general safe harbor for due diligence, unsolicited transfers, or network-level irreversibility. A suspicious activity report or a request through existing consent processes may form part of an escalation, but official materials do not present either as an automatic defense to Section 17C. Analysis still relates to the benefit, its link to the IRGC, facts known to the person, and subsequent conduct.

Recipients typically cannot reject or reverse an incoming blockchain transfer at the network level, though separate account or issuer controls may restrict its subsequent use.

Therefore, the first crypto test of this designation will focus on whether UK-connected recipients and intermediaries can reconstruct a reliable record on attribution and knowledge, as wallet intelligence evolves.

From July 17, this evidence timeline could lead to criminal risk measured in years, even if the transfer itself settled in seconds.

Trending Cryptos

Related Questions

QAccording to the article, what new criminal risk has been introduced for UK crypto businesses and individuals regarding transactions linked to Iran's Islamic Revolutionary Guard Corps (IRGC)?

AAccording to the article, the new criminal risk is outlined in Section 17C of the UK's 2023 National Security Act. It states that a person commits an offence if they obtain, accept, or retain a material benefit, and they know (or ought reasonably to know) that the benefit is from a designated entity like the IRGC. This can carry a maximum penalty of 14 years' imprisonment.

QWhy does the technical nature of blockchain settlement make compliance challenging under the new UK law?

ABlockchain settlement is challenging because a transaction can be finalized on the network before a recipient can reject it. Furthermore, a wallet address might only be attributed to a designated entity like the IRGC *after* the transaction is completed. This creates a critical issue of timing and evidence: what the recipient knew about the wallet's ownership and when they knew it.

QHow does the designation of the IRGC under Schedule 6A differ from traditional financial sanctions under UK law?

ADesignation under Schedule 6A of the National Security Act creates a new criminal offence for receiving benefits from the designated entity. It does NOT automatically trigger the asset freezing and transaction prohibitions that come with traditional financial sanctions. Therefore, a stablecoin issuer, for example, is not legally required to freeze tokens solely based on this designation; liability for receiving the funds rests on the individual or business that obtained or retained the value.

QWhat are some practical steps UK-related crypto firms should consider to manage the new risk, as suggested in the article?

AThe article suggests firms should review and possibly enhance their controls to create reliable timelines of evidence. This includes: separately mapping designated entities from standard sanctions lists; documenting the source, confidence level, and timing of wallet attributions; re-screening earlier deposits when attribution data changes; linking on-chain findings with client and counterparty information; escalating uncertain matches properly; and meticulously documenting decisions regarding access, retention, and reporting.

QDoes a transaction merely involving an Iranian counterparty or wallet automatically constitute a crime under the new UK law?

ANo, a transaction involving an Iranian counterparty or wallet does NOT automatically establish a crime. The prosecution must still prove the necessary link to the specifically designated entity (the IRGC) and the required subjective element—that the recipient knew or ought reasonably to have known that the benefit came from that designated entity.

Related Reads

Who Decides the Rules of Bitcoin? BIP-110 Ignites Governance Debate

Bitcoin's governance is once again at the center of a heated debate, this time ignited by BIP-110, the "Reduced Data Temporary Softfork." This proposal aims to curb non-monetary data (like inscriptions and Runes) by introducing seven new consensus-layer restrictions over a year, such as limiting new output scripts to 34 bytes and restoring the OP_RETURN cap to 83 bytes. The controversy stems from BIP-110's fundamental shift: it moves the battle against "spam" from node relay and miner policies to the consensus layer, rendering currently valid transactions invalid. Supporters, arguing that default policy governance has failed (highlighted by Bitcoin Core v30's relaxation of OP_RETURN limits), see this as necessary to protect node resources and Bitcoin's monetary focus. Opponents, led by figures like Michael Saylor and Adam Back, warn it dangerously centralizes governance. Saylor listed 110 reasons against it, criticizing its low 55% miner activation threshold and potential for chain splits. Back emphasized Bitcoin's "permissionless" ethos, arguing no single group should impose value judgments via consensus rules. Further complicating matters, technical critiques suggest BIP-110 may be technically circumventable, and a "BlockSlop" vulnerability in its upgrade path poses a consensus risk. The debate has drawn in diverse stakeholders: miners (with pools like Ocean signaling support and Foundry polling clients), node operators (like Bitcoin Knots), and new players like corporate treasury holder MicroStrategy (Saylor), whose market influence adds a novel dimension. Ultimately, BIP-110 acts as a governance stress test, exposing the unresolved question: who decides Bitcoin's rules? It pits the authority of miners, node operators, developers, and capital holders against each other, with each side claiming to defend Bitcoin's core principles of neutrality and security.

marsbit9m ago

Who Decides the Rules of Bitcoin? BIP-110 Ignites Governance Debate

marsbit9m ago

Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate

Title: Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate A new technical proposal, BIP-110 (Reduced Data Temporary Softfork), has sparked a fundamental governance debate within the Bitcoin community. It aims to impose new consensus rules for one year to limit non-financial data (like inscriptions and Runes) on-chain, moving beyond simple node and miner policy filters to invalidate currently valid transactions. Supporters argue that default policies have failed due to workarounds, necessitating consensus-layer changes to protect Bitcoin's core monetary function from data spam. Critics, including Michael Saylor and Adam Back, contend this dangerously centralizes judgment, undermines permissionlessness, and sets a risky governance precedent. They advocate for market-based solutions like fees or Layer 2s instead. The debate exposes deeper tensions: miners are divided on activation; node operators assert their sovereignty; Bitcoin Core developers influence defaults without direct accountability; and large corporate holders like MicroStrategy now wield narrative influence. Technically, BIP-110 may not fully block data and carries a disclosed consensus bug risk. Ultimately, BIP-110 acts as a stress test, forcing the community to confront the unresolved question: who legitimately decides what Bitcoin is and how it evolves, amidst competing claims from miners, nodes, developers, and capital holders.

链捕手21m ago

Who Decides Bitcoin's Rules? BIP-110 Ignites Governance Debate

链捕手21m ago

Zcash's New Node Zakura Goes Live: Privacy Payments Can Reach 50,000 TPS, Aiming to Rival Visa and Mastercard

Zcash, a privacy-focused cryptocurrency, has launched a new full node software called Zakura version 1.0.0. Developed by Zcash co-founder Sean Bowe and Dev Ojha, with private ZEC donations, its goal is to enable Zcash to process over 50,000 transactions per second (TPS)—matching the scale of Visa and Mastercard—while maintaining full transaction privacy and verifiability. This addresses a key bottleneck, as Zcash currently handles only about 1 private transaction per second. Zakura is a fork of the Zcash Foundation's Zebra node. It features chain pruning and snapshots, reducing disk usage and allowing new nodes to sync in under two minutes. It also offers compatibility with the legacy `zcashd` client interface. The scalability challenge stems from the large data size of privacy proofs. Bowe's Tachyon project aims to use recursive proofs to reduce consensus-layer data needs from ~500 MB/s to ~100 MB/s. For wallet scalability, Valar Group is researching Private Information Retrieval (PIR) tech to allow wallets to fetch their data privately. Zakura supports fast block propagation and the upcoming "Ironwood" network upgrade (NU6.3), scheduled for activation around July 28th. Ironwood was created to contain a critical inflation bug discovered in the Orchard shielded pool in May 2024. The fix uses "turnstiles" to trap any counterfeit ZEC created during the vulnerability period within the shielded pool, preventing it from entering circulation and restoring supply integrity.

marsbit36m ago

Zcash's New Node Zakura Goes Live: Privacy Payments Can Reach 50,000 TPS, Aiming to Rival Visa and Mastercard

marsbit36m ago

Replicating the "DeepSeek Moment"? Wall Street Unanimously Says: Kimi K3 Instead Strengthens Computing Power Demand

Title: Wall Street Sees Kimi K3 as a Catalyst for Compute Demand, Not a "DeepSeek Moment 2.0" Summary: Following the release of Moonshot AI's powerful open-source model Kimi K3, initial market reaction mirrored the "DeepSeek moment" that sparked a sell-off in compute stocks earlier in 2025, fearing reduced demand for AI infrastructure. However, major Wall Street banks including UBS, Nomura, BofA, and Citi argue the opposite: K3 will accelerate, not weaken, demand for compute, memory, storage, and networking. Their analysis centers on K3's specifications—2.8 trillion parameters, 1M token context, and MoE architecture—which represent a "scale" story rather than a pure "efficiency" one like DeepSeek R1. These features increase pressure on inference, memory (especially KV cache), and storage. Analysts invoke Jevons Paradox: as high-quality models become more affordable (K3 is cheaper than top closed models but not the cheapest), usage and token volumes expand, ultimately increasing total compute consumption. The reports highlight that competition will force leading US AI labs (OpenAI, Anthropic, Google) to invest more in training and iteration to maintain their edge. Furthermore, the rise of capable open-source models like K3 is expanding the global AI developer ecosystem, with Chinese models now accounting for over 45% of developer traffic. Key beneficiaries identified across the AI infrastructure chain include memory/storage players (e.g., Micron, Samsung), compute leaders (Nvidia, TSMC), networking suppliers (due to "super-node" cluster needs for deploying K3), and cloud platforms (e.g., Alibaba) that host diverse model ecosystems. The consensus is that stronger open-source models are an entry point for the next wave of infrastructure demand diffusion, provided workload growth outpaces efficiency gains.

链捕手39m ago

Replicating the "DeepSeek Moment"? Wall Street Unanimously Says: Kimi K3 Instead Strengthens Computing Power Demand

链捕手39m ago

Trading

Spot

Hot Articles

How to Buy ONE

Welcome to HTX.com! We've made purchasing Harmony (ONE) simple and convenient. Follow our step-by-step guide to embark on your crypto journey.Step 1: Create Your HTX AccountUse your email or phone number to sign up for a free account on HTX. Experience a hassle-free registration journey and unlock all features.Get My AccountStep 2: Go to Buy Crypto and Choose Your Payment MethodCredit/Debit Card: Use your Visa or Mastercard to buy Harmony (ONE) instantly.Balance: Use funds from your HTX account balance to trade seamlessly.Third Parties: We've added popular payment methods such as Google Pay and Apple Pay to enhance convenience.P2P: Trade directly with other users on HTX.Over-the-Counter (OTC): We offer tailor-made services and competitive exchange rates for traders.Step 3: Store Your Harmony (ONE)After purchasing your Harmony (ONE), store it in your HTX account. Alternatively, you can send it elsewhere via blockchain transfer or use it to trade other cryptocurrencies.Step 4: Trade Harmony (ONE)Easily trade Harmony (ONE) on HTX's spot market. Simply access your account, select your trading pair, execute your trades, and monitor in real-time. We offer a user-friendly experience for both beginners and seasoned traders.

4.4k Total ViewsPublished 2024.03.29Updated 2026.06.02

How to Buy ONE

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of ONE (ONE) are presented below.

活动图片